Network Packet Spoofing Vulnerability in GRE and GRE6 Protocols by IETF
CVE-2024-7595
6.5MEDIUM
Key Information:
- Vendor
- Ietf
- Status
- Rfc2784 - Generic Routing Encapsulation (gre)
- Vendor
- CVE Published:
- 5 February 2025
Summary
The GRE and GRE6 Protocols allow an attacker to exploit a weakness in the source validation of network packets. This lack of proper validation can lead to the spoofing of packets and unauthorized routing of network traffic through an exposed interface. As a result, this vulnerability may enable various network security issues including access control bypass and unexpected behaviors in network communication.
Affected Version(s)
RFC2784 - Generic Routing Encapsulation (GRE) STD 1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved